Skip to content
Branch: master
Find file Copy path
Fetching contributors…
Cannot retrieve contributors at this time
30 lines (16 sloc) 1.11 KB

Motorola SetStaticRouteSettings CMD Injection


Version: The latest firmware:

Vulnerability Type: Command Injection

Institution: 360 ESG / Legendsec Information Technology(Beijing)Inc..

Vulnerability Description

A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetSmartQoSSettings API function, , as demonstrated by shell metacharacters in the smartqos_priority_devices field


martqos_upstream_shapingrate, smartqos_downstream_shapingrate, smartqos_priority_devices, smartqos_normal_devices, smartqos_express_devices all these fields are vulnerable.

You can’t perform that action at this time.